DSA-4385-1 dovecot -- dovecotID: oval:org.secpod.oval:def:603628 | Date: (C)2019-02-07 (M)2023-12-20 |
Class: PATCH | Family: unix |
halfdog discovered an authentication bypass vulnerability in the Dovecot email server. Under some configurations Dovecot mistakenly trusts the username provided via authentication instead of failing. If there is no additional password verification, this allows the attacker to login as anyone else in the system. Only installations using: auth_ssl_require_client_cert = yes auth_ssl_username_from_cert = yes are affected by this flaw.
Product: |
dovecot-pgsql |
dovecot-mysql |
dovecot-sieve |
dovecot-core |
dovecot-ldap |
dovecot-solr |
dovecot-sqlite |
dovecot-dbg |
dovecot-pop3d |
dovecot-imapd |
dovecot-managesieved |
dovecot-lucene |
dovecot-gssapi |
dovecot-dev |
dovecot-lmtpd |